Skip to content

Conversation

@bwplotka
Copy link
Collaborator

@bwplotka bwplotka commented Oct 30, 2025

  • Synchronized manifests from 0.15 for the correct base images.
  • Go deps vuln upgrades
  • Upgrade Go image versions to latest patch
  • Upgraded manually distroless bash to latest gke_distroless_20251007.00_p0
  • Fixed GCM e2e tests misalignment with the latest changes

Used script:

SYNC_DOCKERFILES_FROM=origin/release/0.15 BRANCH=release/0.12 PR_BRANCH=vulnfix012 CHECKOUT_DIR=~/Repos bash ./hack/release-vulnfix.sh

@bwplotka bwplotka changed the title chore: 0.12: bump distroless bash and Go images (and deps) to fix vulns chore: 0.12: fix vulnerabilities Oct 30, 2025
@bwplotka bwplotka changed the title chore: 0.12: fix vulnerabilities chore: fix 0.12.3 vulnerabilities Oct 30, 2025
@bwplotka
Copy link
Collaborator Author

image

This is fun. It's because we drop compute indirect dep:

image

@bwplotka bwplotka merged commit 7a52547 into release/0.12 Oct 30, 2025
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants